Red Hat released RHSA-2024:6990, an Important security update for the real-time kernel on Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions on x86_64. The update delivers kernel-rt-5.14.0-70.117.1.rt21.189.el9_0, addressing 11 Linux kernel vulnerabilities across sparse-memory handling, networking, ACPICA, RDMA, vsock, perf, SUNRPC, and mac80211 Wi-Fi components. Red Hat did not report active exploitation of the flaws.
Notable fixes include CVE-2023-52489, a locally exploitable sparse-memory race condition that can compromise availability through denial of service when compaction processes device-memory PFNs, and CVE-2024-40995, which can trigger an infinite loop and system-wide task hangs in the traffic-control action API when multiple actions use the same index. The advisory also includes a fix for CVE-2021-47393 affecting the mlxreg-fan hardware-monitoring driver. Administrators should install the updated kernel-rt package and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:2950 for the RHEL 8 kernel-rt package and RHSA-2024:3138 for the RHEL 8 kernel package, both addressing CVE-2023-52489.
Red Hat released RHSA-2024:2394, updating the RHEL 9 kernel to remediate CVE-2023-52489.
Red Hat published its record for CVE-2023-52489, a moderate-severity Linux kernel sparse-memory race condition that can affect system availability.
Red Hat released RHSA-2024:10262, updating the RHEL 8.8 Extended Update Support kernel package to remediate CVE-2023-52489.
Red Hat released RHSA-2024:8613 and RHSA-2024:8614, updating RHEL 9.2 Extended Update Support kernel and kernel-rt packages to address CVE-2023-52489.
Red Hat released RHSA-2024:6990 and RHSA-2024:6991 for RHEL 9.0 Update Services for SAP Solutions, fixing CVE-2023-52489 in kernel-rt and kernel packages. RHSA-2024:6990 required affected systems to reboot after installation for the update to take effect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.